DocumentCode :
3242361
Title :
Behavior based network traffic analysis tool
Author :
Kakuru, Sindhu
Author_Institution :
Electr. Eng. Dept., San Jose State Univ., San Jose, CA, USA
fYear :
2011
fDate :
27-29 May 2011
Firstpage :
649
Lastpage :
652
Abstract :
Pattern matching systems are mainly based on network models, which are formed from detailed analysis of user statistics and network traffic. These models are used in developing traffic analysis tools. This paper focuses on development of a behavior analysis tool on any operating system and its use on detecting internal active/passive attacks. Many kinds of tools and firewalls are in market to help network administrator to prevent intrusion from outside network, but very few tools to stop attacks from internal part of the network. This tool provides a way to detect any unusual behavior by a legitimate user in a network. It uses packet sniffer like Wireshark to record log traffic over a network. Furthermore, behavioral analysis is carried in two phases. In the first phase, Wireshark records the user´s interaction with the network for a period of time and is stored in database. In second phase, current activity is compared to the past activity and notifies any new behavior to network administrator. This tool adds an additional layer of security along with the intrusion detection systems available from any network attacks. Many additional features can be incorporated in this tool for future enhancement.
Keywords :
pattern matching; security of data; Wireshark; behavior analysis tool; behavior based network traffic analysis tool; behavioral analysis; firewalls; intrusion detection system; log traffic; network administrator; network model; operating system; packet sniffer; pattern matching system; user statistics; Electronic publishing; Filtering; Information services; Internet; Network behavior analysis (NBA); Packet capture; network administrator (NA);
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communication Software and Networks (ICCSN), 2011 IEEE 3rd International Conference on
Conference_Location :
Xi´an
Print_ISBN :
978-1-61284-485-5
Type :
conf
DOI :
10.1109/ICCSN.2011.6014810
Filename :
6014810
Link To Document :
بازگشت